Overview
Websense Triton Unified Security Center 7.7.3 and possibly earlier versions contains an information disclosure vulnerability which could allow an authenticated attacker to view stored credentials of a possibly higher privileged user.
Description
CWE-200: Information Exposure When logged into the Websense Triton Unified Security Center 7.7.3 and possibly earlier versions with any permission level, it is possible to navigate to the “Log Database” or “User Directories” portions of the “Settings” module. In either section, it is possible to use a web browser to “Inspect Elements” within the page. |
Impact
An authenticated attacker can view stored credentials of a possibly higher privileged user. |
Solution
Update
Additional information can be found in Websense V7.7.3 HF31 Manager Password Vulnerability issue advisory. |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 3.5 | AV:N/AC:M/Au:S/C:P/I:N/A:N |
Temporal | 2.9 | E:F/RL:OF/RC:C |
Environmental | 0.9 | CDP:L/TD:L/CR:ND/IR:ND/AR:ND |
References
Acknowledgements
Thanks to Patrick Kelley of Critical Assets for reporting this vulnerability.
This document was written by Michael Orlando.
Other Information
CVE IDs: | CVE-2014-0347 |
Date Public: | 2014-03-24 |
Date First Published: | 2014-04-07 |
Date Last Updated: | 2014-04-07 17:09 UTC |
Document Revision: | 17 |